WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 2,051–2,100 of 2,114 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 42 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion ≤ 5.9.8 CVE-2024-1172 Wordfence
6.1 Medium Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.8 CVE-2024-0821 Wordfence
6.4 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 7.1.6 CVE-2024-1054 Wordfence
7.3 High Oliver POS – A WooCommerce Point of Sale (POS) Plugin oliver-pos Broken Access Control A WooCommerce Point of Sale (POS) <= 2.4.2.1 - Missing Authorization No login needed ≤ 2.4.2.0 CVE-2024-0702 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.8 CVE-2024-1276 Wordfence
5.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Improper Authorization via submit_review No login needed ≤ 5.38.12 CVE-2024-1044 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.8 CVE-2024-1236 Wordfence
9.8 Critical Piraeus Bank WooCommerce Payment Gateway Plugin woo-payment-gateway-for-piraeus-bank SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.6.5.1 CVE-2024-0610 Wordfence
8.7 High ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks Plugin product-blocks PHP Object Injection Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2024-23512 Patchstack
8.2 High Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – Plugin mage-eventpress PHP Object Injection WordPress Event Manager for WooCommerce Plugin <= 4.1.1 is vulnerable to PHP Object Injection ≤ 4.1.1 Fixed in 4.1.2 CVE-2024-24796 Patchstack
6.5 Medium Active Products Tables for WooCommerce. Professional products tables for WooCommerce store Plugin profit-products-tables-for-woocommerce Cross-Site Scripting WordPress Active Products Tables for WooCommerce Plugin <= 1.0.6 is vulnerable to Cross Site Scripting (XSS) ≤ 1.0.6 Fixed in 1.0.6.1 CVE-2023-51480 Patchstack
6.5 Medium Pay with Vipps and MobilePay for WooCommerce Plugin woo-vipps Cross-Site Scripting WordPress Pay with Vipps for WooCommerce Plugin <= 1.14.13 is vulnerable to Cross Site Scripting (XSS) ≤ 1.14.13 Fixed in 1.14.14 CVE-2023-51485 Patchstack
5.3 Medium Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin Plugin wp-event-solution Broken Access Control Eventin <= 3.3.50 - Missing Authorization to Unauthenticated Events Export No login needed ≤ 3.3.50 CVE-2024-1122 Wordfence
5.9 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Scripting WordPress BEAR Plugin <= 1.1.4 is vulnerable to Cross Site Scripting (XSS) ≤ 1.1.4 Fixed in 1.1.4.1 CVE-2024-24834 Patchstack
7.1 High Portugal CTT Tracking for WooCommerce Plugin portugal-ctt-tracking-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 Fixed in 2.2 CVE-2024-24878 Patchstack
7.1 High WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc Plugin wp-sms Cross-Site Scripting WordPress WP SMS Plugin <= 6.5.2 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 6.5.2 Fixed in 6.5.3 CVE-2024-24881 Patchstack
5.9 Medium Woocommerce Vietnam Checkout Plugin woo-vietnam-checkout Cross-Site Scripting WordPress Woocommerce Vietnam Checkout Plugin <= 2.0.7 is vulnerable to Cross Site Scripting (XSS) ≤ 2.0.7 Fixed in 2.0.8 CVE-2024-24885 Patchstack
5.9 Medium Product Labels For Woocommerce (Sale Badges) Plugin aco-product-labels-for-woocommerce Cross-Site Scripting WordPress Product Labels For Woocommerce Plugin <= 1.5.3 is vulnerable to Cross Site Scripting (XSS) ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-24886 Patchstack
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scritping ≤ 5.9.4 CVE-2024-0586 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.7 CVE-2024-0954 Wordfence
4.3 Medium Active Products Tables for WooCommerce. Professional products tables for WooCommerce store Plugin profit-products-tables-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.6.1 CVE-2024-0796 Wordfence
5.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl ≤ 5.9.4 CVE-2024-0585 Wordfence
4.3 Medium Active Products Tables for WooCommerce. Professional products tables for WooCommerce store Plugin profit-products-tables-for-woocommerce Broken Access Control Missing Authorization ≤ 1.0.6.1 CVE-2024-0797 Wordfence
5.9 Medium Add Customer for WooCommerce Plugin add-customer-for-woocommerce Cross-Site Scripting WordPress Add Customer for WooCommerce Plugin <= 1.7 is vulnerable to Cross Site Scripting (XSS) ≤ 1.7 Fixed in 1.7.1 CVE-2024-24841 Patchstack
6.5 Medium Product Code for WooCommerce Plugin product-code-for-woocommerce Cross-Site Scripting WordPress Product Code for WooCommerce Plugin <= 1.4.4 is vulnerable to Cross Site Scripting (XSS) ≤ 1.4.4 Fixed in 1.4.5 CVE-2023-51669 Patchstack
5.9 Medium Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Cross-Site Scripting WordPress Stock Locations for WooCommerce Plugin <= 2.5.9 is vulnerable to Cross Site Scripting (XSS) ≤ 2.5.9 Fixed in 2.6.0 CVE-2024-22153 Patchstack
6.1 Medium Biteship for WooCommerce Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed < 2.2.25 Fixed in 2.2.25 CVE-2023-6278 WPScan
7.6 High PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips SQL Injection WordPress WooCommerce PDF Invoices & Packing Slips Plugin <= 3.7.5 is vulnerable to SQL Injection ≤ 3.7.5 Fixed in 3.7.6 CVE-2024-22147 Patchstack
5.3 Medium Category Discount Woocommerce Plugin woo-product-category-discount Broken Access Control Missing Authorization via wpcd_save_discount() No login needed ≤ 4.12 CVE-2024-0617 Wordfence
8.0 High Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Arbitrary File Upload WordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Upload ≤ 2.4.3 Fixed in 2.4.4 CVE-2024-22135 Patchstack
8.0 High Product Import Export for WooCommerce Plugin product-import-export-for-woo Arbitrary File Upload WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload ≤ 2.3.7 Fixed in 2.3.8 CVE-2024-22152 Patchstack
4.8 Medium Product Enquiry for WooCommerce Plugin gm-woocommerce-quote-popup Cross-Site Scripting Admin+ Stored XSS < 3.1 Fixed in 3.1 CVE-2023-6626 WPScan
4.3 Medium Product Enquiry for WooCommerce Plugin gm-woocommerce-quote-popup Cross-Site Request Forgery Arbitrary Enquiry Deletion via CSRF No login needed < 3.1 Fixed in 3.1 CVE-2023-6625 WPScan
8.2 High Montonio for WooCommerce Plugin montonio-for-woocommerce Server-Side Request Forgery Server Side Request Forgery (SSRF) vulnerability affecting multiple WordPress plugins No login needed ≤ 6.0.1, ≤ 1.5.8, ≤ 4.6.6, … Fixed in 6.0.2 CVE-2022-40700 Patchstack
9.8 Critical Stripe Payment Plugin for WooCommerce Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.7.9 CVE-2024-0705 Wordfence
5.4 Medium Advanced Local Pickup for WooCommerce Plugin advanced-local-pickup-for-woocommerce Broken Access Control WordPress Advanced Local Pickup for WooCommerce Plugin <= 1.5.2 is vulnerable to Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2022-40702 Patchstack
5.4 Medium Cart2Cart: Magento to WooCommerce Migration Plugin cart2cart-magento-to-woocommerce-migration Broken Access Control WordPress Cart2Cart: Magento to WooCommerce Migration Plugin <= 2.0.0 is vulnerable to Broken Access Control ≤ 2.0.0 CVE-2023-34379 Patchstack
6.3 Medium Advanced Dynamic Pricing for WooCommerce Plugin advanced-dynamic-pricing-for-woocommerce Broken Access Control WordPress Advanced Dynamic Pricing for WooCommerce Plugin <= 4.1.5 is vulnerable to Broken Access Control ≤ 4.1.5 Fixed in 4.1.6 CVE-2022-40203 Patchstack
4.3 Medium Sales Report Email for WooCommerce Plugin woo-advanced-sales-report-email Broken Access Control WordPress Sales Report Email for WooCommerce Plugin <= 2.8 is vulnerable to Broken Access Control ≤ 2.8 Fixed in 2.9 CVE-2022-38141 Patchstack
6.1 Medium Product Enquiry for WooCommerce Plugin gm-woocommerce-quote-popup Cross-Site Scripting Reflected XSS No login needed < 3.2 Fixed in 3.2 CVE-2023-7151 WPScan
7.5 High All in One B2B for WooCommerce Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.3 CVE-2023-4703 WPScan
6.1 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Cross-Site Scripting Reflected XSS No login needed < 4.7.2 Fixed in 4.7.2 CVE-2023-0479 WPScan
5.4 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Contributor+ Stored XSS < 5.17.0 Fixed in 5.17.0 CVE-2023-0079 WPScan
4.3 Medium WooCommerce Plugin woocommerce Broken Access Control Subscriber+ Arbitrary Comment Deletion < 6.2.1 Fixed in 6.2.1 CVE-2022-0775 WPScan
5.3 Medium WPGraphQL WooCommerce Plugin Information Disclosure Unauthenticated Coupon Codes Disclosure No login needed < 0.12.4 Fixed in 0.12.4 CVE-2022-1563 WPScan
6.1 Medium Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Cross-Site Scripting Unauthenticated Reflected Cross-Site Scripting (XSS) No login needed < 1.5.4.7 Fixed in 1.5.4.7 CVE-2021-24432 WPScan
8.8 High WooCommerce Currency Switcher Plugin Local File Inclusion Authenticated (Low Privilege) Local File Inclusion < 1.3.7 Fixed in 1.3.7 CVE-2021-24566 WPScan
5.4 Medium FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Broken Access Control Currency Switcher Professional for WooCommerce <= 1.4.1.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.4.1.6 CVE-2023-6556 Wordfence
7.2 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Arbitrary File Upload Authenticated (Shop Manager+) Arbitrary File Upload ≤ 2.4.8 CVE-2023-6558 Wordfence
8.8 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 5.38.9 CVE-2023-6979 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only